<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:16:40 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:19793 — Important: bind9.16 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:19793</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bind9.16, AlmaLinux:8: bind9.16-chroot, AlmaLinux:8: bind9.16-devel, AlmaLinux:8: bind9.16-dnssec-utils, AlmaLinux:8: bind9.16-doc, AlmaLinux:8: bind9.16-libs, AlmaLinux:8: bind9.16-license, AlmaLinux:8: bind9.16-utils, AlmaLinux:8: python3-bind9.16&lt;/p&gt;
&lt;p&gt;The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* bind: Cache poisoning attacks with unsolicited RRs (CVE-2025-40778)
  * bind: Cache poisoning due to weak PRNG (CVE-2025-40780)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bind9.16, AlmaLinux:8: bind9.16-chroot, AlmaLinux:8: bind9.16-devel, AlmaLinux:8: bind9.16-dnssec-utils, AlmaLinux:8: bind9.16-doc, AlmaLinux:8: bind9.16-libs, AlmaLinux:8: bind9.16-license, AlmaLinux:8: bind9.16-utils, AlmaLinux:8: python3-bind9.16&lt;/p&gt;
&lt;p&gt;The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* bind: Cache poisoning attacks with unsolicited RRs (CVE-2025-40778)
  * bind: Cache poisoning due to weak PRNG (CVE-2025-40780)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:19793</guid>
    </item>
    <item>
      <title>bdu:2025-13637</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-13637</link>
      <description>bdu:2025-13637</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-13637</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-40778</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-40778</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: bind, Alpaquita:25: bind, Alpaquita:stream: bind&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: bind, Alpaquita:25: bind, Alpaquita:stream: bind&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-40778</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0913 — De multiples vulnérabilités ont été découvertes dans ISC BIND. Elles permettent à un attaquant de provoquer un déni de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0913</link>
      <description>certfr-2025-avi-0913</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0913</guid>
    </item>
    <item>
      <title>cnvd-2025-26736</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-26736</link>
      <description>cnvd-2025-26736</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-26736</guid>
    </item>
    <item>
      <title>EUVD-2026-271438</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-271438</link>
      <description>EUVD-2026-271438</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-271438</guid>
    </item>
    <item>
      <title>fkie_cve-2025-40778</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40778</link>
      <description>&lt;p&gt;Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache.
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache.
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-40778</guid>
    </item>
    <item>
      <title>GHSA-xmqp-6cj2-2hh3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xmqp-6cj2-2hh3</link>
      <description>&lt;p&gt;Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache.
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache.
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xmqp-6cj2-2hh3</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-40778 — Cache poisoning attacks with unsolicited RRs</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-40778</link>
      <description>msrc_CVE-2025-40778</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-40778</guid>
    </item>
    <item>
      <title>OESA-2025-2653 — bind security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2653</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: bind&lt;/p&gt;
&lt;p&gt;Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols and provides an openly redistributable reference implementation of the major components of the Domain Name System. This package includes the components to operate a DNS server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.(CVE-2025-40778)&lt;/p&gt;
&lt;p&gt;In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.(CVE-2025-40780)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: bind&lt;/p&gt;
&lt;p&gt;Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols and provides an openly redistributable reference implementation of the major components of the Domain Name System. This package includes the components to operate a DNS server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.(CVE-2025-40778)&lt;/p&gt;
&lt;p&gt;In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.(CVE-2025-40780)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2653</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15659-1 — bind-9.20.15-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15659-1</link>
      <description>&lt;p&gt;bind-9.20.15-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bind-9.20.15-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15659-1</guid>
    </item>
    <item>
      <title>RHSA-2025:19912 — Red Hat Security Advisory: bind security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:19912</link>
      <description>&lt;p&gt;bind: Resource exhaustion via malformed DNSKEY handling bind: Cache poisoning attacks with unsolicited RRs bind: Cache poisoning due to weak PRNG&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bind: Resource exhaustion via malformed DNSKEY handling bind: Cache poisoning attacks with unsolicited RRs bind: Cache poisoning due to weak PRNG&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:19912</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:3976-1 — Security update for bind</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:3976-1</link>
      <description>&lt;p&gt;Security update for bind&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for bind&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:3976-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-40778</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40778</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: bind9, Ubuntu:Pro:16.04:LTS: bind9, Ubuntu:Pro:18.04:LTS: bind9, Ubuntu:18.04:LTS: isc-dhcp, Ubuntu:Pro:20.04:LTS: bind9, Ubuntu:20.04:LTS: bind9-libs, Ubuntu:22.04:LTS: bind9, Ubuntu:22.04:LTS: bind9-libs, Ubuntu:24.04:LTS: bind9, Ubuntu:24.04:LTS: isc-dhcp and 4 more&lt;/p&gt;
&lt;p&gt;Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: bind9, Ubuntu:Pro:16.04:LTS: bind9, Ubuntu:Pro:18.04:LTS: bind9, Ubuntu:18.04:LTS: isc-dhcp, Ubuntu:Pro:20.04:LTS: bind9, Ubuntu:20.04:LTS: bind9-libs, Ubuntu:22.04:LTS: bind9, Ubuntu:22.04:LTS: bind9-libs, Ubuntu:24.04:LTS: bind9, Ubuntu:24.04:LTS: isc-dhcp and 4 more&lt;/p&gt;
&lt;p&gt;Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40778</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2392 — Internet Systems Consortium BIND: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2392</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um Dateien zu manipulieren und um einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um Dateien zu manipulieren und um einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2392</guid>
    </item>
  </channel>
</rss>
